From 50b55e486f8e7baf901dc45508f63f65a6d1fd94 Mon Sep 17 00:00:00 2001 From: Austin Horstman Date: Fri, 7 Nov 2025 17:00:48 -0600 Subject: [PATCH 01/13] yaziPlugins: update on 2025-11-07 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - mediainfo: 25.5.31-unstable-2025-08-28 → 25.5.31-unstable-2025-11-04 - recycle-bin: 0-unstable-2025-10-25 → 0-unstable-2025-11-03 - sudo: 0-unstable-2025-09-22 → 0-unstable-2025-11-05 Signed-off-by: Austin Horstman --- pkgs/by-name/ya/yazi/plugins/mediainfo/default.nix | 6 +++--- pkgs/by-name/ya/yazi/plugins/recycle-bin/default.nix | 6 +++--- pkgs/by-name/ya/yazi/plugins/sudo/default.nix | 6 +++--- 3 files changed, 9 insertions(+), 9 deletions(-) diff --git a/pkgs/by-name/ya/yazi/plugins/mediainfo/default.nix b/pkgs/by-name/ya/yazi/plugins/mediainfo/default.nix index c5692e7db0cf..8e046356a4a2 100644 --- a/pkgs/by-name/ya/yazi/plugins/mediainfo/default.nix +++ b/pkgs/by-name/ya/yazi/plugins/mediainfo/default.nix @@ -5,13 +5,13 @@ }: mkYaziPlugin { pname = "mediainfo.yazi"; - version = "25.5.31-unstable-2025-08-28"; + version = "25.5.31-unstable-2025-11-04"; src = fetchFromGitHub { owner = "boydaihungst"; repo = "mediainfo.yazi"; - rev = "2093ab79d47d750c0b74759d2dd93aff8c7ee5c8"; - hash = "sha256-GObz6kpBTT1HuWgsAWlbbzCw2GxZGKLTWaUKKztiTaw="; + rev = "7543154138ffb2bb0c738419af6ff4595152a809"; + hash = "sha256-qWh/2WA1pBhze+g5aDSl4gHk2zJSgnl4WZr74FfNA74="; }; meta = { diff --git a/pkgs/by-name/ya/yazi/plugins/recycle-bin/default.nix b/pkgs/by-name/ya/yazi/plugins/recycle-bin/default.nix index 5de164d5d744..a3e01204d065 100644 --- a/pkgs/by-name/ya/yazi/plugins/recycle-bin/default.nix +++ b/pkgs/by-name/ya/yazi/plugins/recycle-bin/default.nix @@ -5,13 +5,13 @@ }: mkYaziPlugin { pname = "recycle-bin.yazi"; - version = "0-unstable-2025-10-25"; + version = "0-unstable-2025-11-03"; src = fetchFromGitHub { owner = "uhs-robert"; repo = "recycle-bin.yazi"; - rev = "8bb62865fdef06ea27c10367595017c118ef2831"; - hash = "sha256-p7UBJCWvyOHpt2EbjDNJJ0wuPxK425vyy+9lf9al9F0="; + rev = "bce0eb110e2447544fd619f30ff82bfee51a6347"; + hash = "sha256-dj/lKod8I6Fs1Vp2e6AOEmUVSwT12Ck7zT5e4Qsmzt0="; }; meta = { diff --git a/pkgs/by-name/ya/yazi/plugins/sudo/default.nix b/pkgs/by-name/ya/yazi/plugins/sudo/default.nix index c895b5a30754..22bc4af3eb35 100644 --- a/pkgs/by-name/ya/yazi/plugins/sudo/default.nix +++ b/pkgs/by-name/ya/yazi/plugins/sudo/default.nix @@ -5,13 +5,13 @@ }: mkYaziPlugin { pname = "sudo.yazi"; - version = "0-unstable-2025-09-22"; + version = "0-unstable-2025-11-05"; src = fetchFromGitHub { owner = "TD-Sky"; repo = "sudo.yazi"; - rev = "8148f9101d0aeb8eed5ba2b7e943d51963f14bd9"; - hash = "sha256-old+I3UlgMWfG0HuKEdIkAO2/4KNRLAWj0l+lB9+aZU="; + rev = "86205aa8044f10b02471be1087f3381bbadc967e"; + hash = "sha256-mpQLij+Sg88RarCC+0u7JfZ2EqcX4gB7jvy8bfBt90w="; }; meta = { From af892a833bbd5b61700f4409bd96afbd708eb9d6 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 8 Nov 2025 03:03:04 +0000 Subject: [PATCH 02/13] cargo-semver-checks: 0.44.0 -> 0.45.0 --- pkgs/by-name/ca/cargo-semver-checks/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ca/cargo-semver-checks/package.nix b/pkgs/by-name/ca/cargo-semver-checks/package.nix index a9c71a50977f..9c5470d90d9f 100644 --- a/pkgs/by-name/ca/cargo-semver-checks/package.nix +++ b/pkgs/by-name/ca/cargo-semver-checks/package.nix @@ -11,16 +11,16 @@ rustPlatform.buildRustPackage rec { pname = "cargo-semver-checks"; - version = "0.44.0"; + version = "0.45.0"; src = fetchFromGitHub { owner = "obi1kenobi"; repo = "cargo-semver-checks"; tag = "v${version}"; - hash = "sha256-QU8vLdq129gcGi8/VfjflY6zkIXXam/Ri2zjbO3sPNg="; + hash = "sha256-sDx449IXsFUeNL7rXbGC+HUshwqcbpjvGwl0WIJZmwo="; }; - cargoHash = "sha256-0oPAIhhBcCwZT8sD2PWJ5ZDuMMFvmwxhyOXJWA9+jZg="; + cargoHash = "sha256-meF1qnISB60JXKZyYfnwE2LywGqKEVgZbwzZQEZ1Cmc="; nativeBuildInputs = [ cmake From ed09228baeedcb2db0911a9557a45efeccf2e1a4 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 8 Nov 2025 12:30:02 +0000 Subject: [PATCH 03/13] pv: 1.9.44 -> 1.10.0 --- pkgs/by-name/pv/pv/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/pv/pv/package.nix b/pkgs/by-name/pv/pv/package.nix index b612e525a7e8..35611cd72ff6 100644 --- a/pkgs/by-name/pv/pv/package.nix +++ b/pkgs/by-name/pv/pv/package.nix @@ -6,11 +6,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "pv"; - version = "1.9.44"; + version = "1.10.0"; src = fetchurl { url = "https://www.ivarch.com/programs/sources/pv-${finalAttrs.version}.tar.gz"; - hash = "sha256-4TDJ4Ysebp4u+VvsYRfHLLm+J6G4/+l/ynh+TI4BRWI="; + hash = "sha256-mY5xdBnALuc1rqC41X+cvhES9A9LlHo5uiYRpBW2TaA="; }; meta = { From 498ffd776e42ed651d53ac48187590409a25bc58 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 8 Nov 2025 18:37:15 +0000 Subject: [PATCH 04/13] p2pool: 4.11 -> 4.12 --- pkgs/by-name/p2/p2pool/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/p2/p2pool/package.nix b/pkgs/by-name/p2/p2pool/package.nix index 262a38bf5c11..fe56cad06d58 100644 --- a/pkgs/by-name/p2/p2pool/package.nix +++ b/pkgs/by-name/p2/p2pool/package.nix @@ -16,13 +16,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "p2pool"; - version = "4.11"; + version = "4.12"; src = fetchFromGitHub { owner = "SChernykh"; repo = "p2pool"; rev = "v${finalAttrs.version}"; - hash = "sha256-qoz7wMI6hheF+Pecfq3pPZRc2H3nkrxKRMWR2qmJdsI="; + hash = "sha256-Yrc36tibHanXZcE3I+xcmkCzBALE09zi1Zg0Lz3qS2g="; fetchSubmodules = true; }; From ce24f735858513b63840b3bab216ee1e4ec76773 Mon Sep 17 00:00:00 2001 From: eljamm Date: Sat, 8 Nov 2025 22:24:42 +0100 Subject: [PATCH 05/13] yaziPlugins.bookmarks: init at 0.2.5-unstable-2025-07-09 --- .../ya/yazi/plugins/bookmarks/default.nix | 23 +++++++++++++++++++ 1 file changed, 23 insertions(+) create mode 100644 pkgs/by-name/ya/yazi/plugins/bookmarks/default.nix diff --git a/pkgs/by-name/ya/yazi/plugins/bookmarks/default.nix b/pkgs/by-name/ya/yazi/plugins/bookmarks/default.nix new file mode 100644 index 000000000000..bb97c06b595e --- /dev/null +++ b/pkgs/by-name/ya/yazi/plugins/bookmarks/default.nix @@ -0,0 +1,23 @@ +{ + lib, + fetchFromGitHub, + mkYaziPlugin, +}: +mkYaziPlugin { + pname = "bookmarks.yazi"; + version = "0.2.5-unstable-2025-07-09"; + + src = fetchFromGitHub { + owner = "dedukun"; + repo = "bookmarks.yazi"; + rev = "9ef1254d8afe88aba21cd56a186f4485dd532ab8"; + hash = "sha256-GQFBRB2aQqmmuKZ0BpcCAC4r0JFKqIANZNhUC98SlwY="; + }; + + meta = { + description = "Yazi plugin that adds the basic functionality of vi-like marks"; + homepage = "https://github.com/dedukun/bookmarks.yazi"; + license = lib.licenses.mit; + maintainers = with lib.maintainers; [ eljamm ]; + }; +} From ce4d7b5e2d194f77a27f43a4b10d82088dfbd79c Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 8 Nov 2025 21:51:24 +0000 Subject: [PATCH 06/13] rebels-in-the-sky: 1.1.0 -> 1.1.2 --- pkgs/by-name/re/rebels-in-the-sky/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/re/rebels-in-the-sky/package.nix b/pkgs/by-name/re/rebels-in-the-sky/package.nix index 67574890a98b..633a78f640e3 100644 --- a/pkgs/by-name/re/rebels-in-the-sky/package.nix +++ b/pkgs/by-name/re/rebels-in-the-sky/package.nix @@ -14,16 +14,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "rebels-in-the-sky"; - version = "1.1.0"; + version = "1.1.2"; src = fetchFromGitHub { owner = "ricott1"; repo = "rebels-in-the-sky"; tag = "v${finalAttrs.version}"; - hash = "sha256-wkYzYKFoMn+cKZUaQn9GRxYXXe60ea6UFjamdrxjJFs="; + hash = "sha256-37sStLh2gZm5aV2czvV7lU+aCUyed8/ZKPRUb02AQQw="; }; - cargoHash = "sha256-6qLIrUa5wvh4TQhl/JQLV0QKtgSQZNT4l6Z+2121BmY="; + cargoHash = "sha256-qj9Utd8mICP7Ulx86PWNusV/7OvfaI4u3qvbp69kYP0="; patches = lib.optionals (!withRadio) [ ./disable-radio.patch From 79fcd29323b1b01f78b5b3a70adcceec55797848 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Sat, 8 Nov 2025 21:21:22 -0800 Subject: [PATCH 07/13] python3Packages.pysaml2: 7.5.2 -> 7.5.4 Diff: https://github.com/IdentityPython/pysaml2/compare/v7.5.2...v7.5.4 Changelog: https://github.com/IdentityPython/pysaml2/blob/v7.5.4/CHANGELOG.md --- .../python-modules/pysaml2/default.nix | 23 +- .../replace-pyopenssl-with-cryptography.patch | 334 ++++++++++++++++++ 2 files changed, 341 insertions(+), 16 deletions(-) create mode 100644 pkgs/development/python-modules/pysaml2/replace-pyopenssl-with-cryptography.patch diff --git a/pkgs/development/python-modules/pysaml2/default.nix b/pkgs/development/python-modules/pysaml2/default.nix index 188bf2e3f80e..9d355760333c 100644 --- a/pkgs/development/python-modules/pysaml2/default.nix +++ b/pkgs/development/python-modules/pysaml2/default.nix @@ -4,16 +4,12 @@ cryptography, defusedxml, fetchFromGitHub, - fetchpatch, paste, poetry-core, pyasn1, pymongo, - pyopenssl, pytestCheckHook, python-dateutil, - pythonOlder, - pytz, repoze-who, requests, responses, @@ -26,14 +22,14 @@ buildPythonPackage rec { pname = "pysaml2"; - version = "7.5.2"; + version = "7.5.4"; pyproject = true; src = fetchFromGitHub { owner = "IdentityPython"; repo = "pysaml2"; tag = "v${version}"; - hash = "sha256-2mvAXTruZqoSBUgfT2VEAnWQXVdviG0e49y7LPK5x00="; + hash = "sha256-DDs0jWONZ78995p7bbyIyZTWHnCI93SsbECqyeo0se8="; }; patches = [ @@ -41,10 +37,8 @@ buildPythonPackage rec { inherit xmlsec; }) # Replaces usages of deprecated/removed pyopenssl APIs - (fetchpatch { - url = "https://github.com/IdentityPython/pysaml2/pull/977/commits/930a652a240c8cd1489429a7d70cf5fa7ef1606a.patch"; - hash = "sha256-kBNvGk5pwVmpW1wsIWVH9wapu6kjFavaTt4e3Llaw2c="; - }) + # https://github.com/IdentityPython/pysaml2/pull/977 + ./replace-pyopenssl-with-cryptography.patch ]; postPatch = '' @@ -54,18 +48,14 @@ buildPythonPackage rec { pythonRelaxDeps = [ "xmlschema" ]; - nativeBuildInputs = [ + build-system = [ poetry-core ]; - propagatedBuildInputs = [ + dependencies = [ cryptography defusedxml - pyopenssl - python-dateutil - pytz requests - setuptools xmlschema ]; @@ -81,6 +71,7 @@ buildPythonPackage rec { pyasn1 pymongo pytestCheckHook + python-dateutil responses ]; diff --git a/pkgs/development/python-modules/pysaml2/replace-pyopenssl-with-cryptography.patch b/pkgs/development/python-modules/pysaml2/replace-pyopenssl-with-cryptography.patch new file mode 100644 index 000000000000..3453f3a68164 --- /dev/null +++ b/pkgs/development/python-modules/pysaml2/replace-pyopenssl-with-cryptography.patch @@ -0,0 +1,334 @@ +diff --git a/pyproject.toml b/pyproject.toml +index 87068b18..03f30491 100644 +--- a/pyproject.toml ++++ b/pyproject.toml +@@ -22,8 +22,6 @@ requires-python = ">= 3.9" + dependencies = [ + "cryptography >=3.1", + "defusedxml", +- "pyopenssl <24.3.0", +- "python-dateutil", + "requests >=2.0.0,<3.0.0", # ^2 means compatible with 2.x + "xmlschema >=2.0.0,<3.0.0" + ] +diff --git a/src/saml2/cert.py b/src/saml2/cert.py +index e90651e4..926aec8a 100644 +--- a/src/saml2/cert.py ++++ b/src/saml2/cert.py +@@ -3,11 +3,13 @@ __author__ = "haho0032" + import base64 + from os import remove + from os.path import join +-from datetime import datetime +-from datetime import timezone ++from datetime import datetime, timedelta, timezone + +-from OpenSSL import crypto +-import dateutil.parser ++from cryptography import x509 ++from cryptography.exceptions import InvalidSignature ++from cryptography.hazmat.primitives import hashes, serialization ++from cryptography.hazmat.primitives.asymmetric import rsa ++from cryptography.x509.oid import NameOID + + import saml2.cryptography.pki + +@@ -36,7 +38,6 @@ class OpenSSLWrapper: + valid_to=315360000, + sn=1, + key_length=1024, +- hash_alg="sha256", + write_to_file=False, + cert_dir="", + cipher_passphrase=None, +@@ -87,8 +88,6 @@ class OpenSSLWrapper: + is 1. + :param key_length: Length of the key to be generated. Defaults + to 1024. +- :param hash_alg: Hash algorithm to use for the key. Default +- is sha256. + :param write_to_file: True if you want to write the certificate + to a file. The method will then return + a tuple with path to certificate file and +@@ -131,49 +130,68 @@ class OpenSSLWrapper: + k_f = join(cert_dir, key_file) + + # create a key pair +- k = crypto.PKey() +- k.generate_key(crypto.TYPE_RSA, key_length) ++ k = rsa.generate_private_key( ++ public_exponent=65537, ++ key_size=key_length, ++ ) + + # create a self-signed cert +- cert = crypto.X509() ++ builder = x509.CertificateBuilder() + + if request: +- cert = crypto.X509Req() ++ builder = x509.CertificateSigningRequestBuilder() + + if len(cert_info["country_code"]) != 2: + raise WrongInput("Country code must be two letters!") +- cert.get_subject().C = cert_info["country_code"] +- cert.get_subject().ST = cert_info["state"] +- cert.get_subject().L = cert_info["city"] +- cert.get_subject().O = cert_info["organization"] # noqa: E741 +- cert.get_subject().OU = cert_info["organization_unit"] +- cert.get_subject().CN = cn ++ subject_name = x509.Name([ ++ x509.NameAttribute(NameOID.COUNTRY_NAME, ++ cert_info["country_code"]), ++ x509.NameAttribute(NameOID.STATE_OR_PROVINCE_NAME, ++ cert_info["state"]), ++ x509.NameAttribute(NameOID.LOCALITY_NAME, ++ cert_info["city"]), ++ x509.NameAttribute(NameOID.ORGANIZATION_NAME, ++ cert_info["organization"]), ++ x509.NameAttribute(NameOID.ORGANIZATIONAL_UNIT_NAME, ++ cert_info["organization_unit"]), ++ x509.NameAttribute(NameOID.COMMON_NAME, cn), ++ ]) ++ builder = builder.subject_name(subject_name) + if not request: +- cert.set_serial_number(sn) +- cert.gmtime_adj_notBefore(valid_from) # Valid before present time +- cert.gmtime_adj_notAfter(valid_to) # 3 650 days +- cert.set_issuer(cert.get_subject()) +- cert.set_pubkey(k) +- cert.sign(k, hash_alg) ++ now = datetime.now(timezone.utc) ++ builder = builder.serial_number( ++ sn, ++ ).not_valid_before( ++ now + timedelta(seconds=valid_from), ++ ).not_valid_after( ++ now + timedelta(seconds=valid_to), ++ ).issuer_name( ++ subject_name, ++ ).public_key( ++ k.public_key(), ++ ) ++ cert = builder.sign(k, hashes.SHA256()) + + try: +- if request: +- tmp_cert = crypto.dump_certificate_request(crypto.FILETYPE_PEM, cert) +- else: +- tmp_cert = crypto.dump_certificate(crypto.FILETYPE_PEM, cert) +- tmp_key = None ++ tmp_cert = cert.public_bytes(serialization.Encoding.PEM) ++ key_encryption = None + if cipher_passphrase is not None: + passphrase = cipher_passphrase["passphrase"] + if isinstance(cipher_passphrase["passphrase"], str): + passphrase = passphrase.encode("utf-8") +- tmp_key = crypto.dump_privatekey(crypto.FILETYPE_PEM, k, cipher_passphrase["cipher"], passphrase) ++ key_encryption = serialization.BestAvailableEncryption(passphrase) + else: +- tmp_key = crypto.dump_privatekey(crypto.FILETYPE_PEM, k) ++ key_encryption = serialization.NoEncryption() ++ tmp_key = k.private_bytes( ++ encoding=serialization.Encoding.PEM, ++ format=serialization.PrivateFormat.TraditionalOpenSSL, ++ encryption_algorithm=key_encryption, ++ ) + if write_to_file: +- with open(c_f, "w") as fc: +- fc.write(tmp_cert.decode("utf-8")) +- with open(k_f, "w") as fk: +- fk.write(tmp_key.decode("utf-8")) ++ with open(c_f, "wb") as fc: ++ fc.write(tmp_cert) ++ with open(k_f, "wb") as fk: ++ fk.write(tmp_key) + return c_f, k_f + return tmp_cert, tmp_key + except Exception as ex: +@@ -198,7 +216,6 @@ class OpenSSLWrapper: + sign_cert_str, + sign_key_str, + request_cert_str, +- hash_alg="sha256", + valid_from=0, + valid_to=315360000, + sn=1, +@@ -222,8 +239,6 @@ class OpenSSLWrapper: + the requested certificate. If you only have + a file use the method read_str_from_file + to get a string representation. +- :param hash_alg: Hash algorithm to use for the key. Default +- is sha256. + :param valid_from: When the certificate starts to be valid. + Amount of seconds from when the + certificate is generated. +@@ -237,27 +252,29 @@ class OpenSSLWrapper: + :return: String representation of the signed + certificate. + """ +- ca_cert = crypto.load_certificate(crypto.FILETYPE_PEM, sign_cert_str) +- ca_key = None +- if passphrase is not None: +- ca_key = crypto.load_privatekey(crypto.FILETYPE_PEM, sign_key_str, passphrase) +- else: +- ca_key = crypto.load_privatekey(crypto.FILETYPE_PEM, sign_key_str) +- req_cert = crypto.load_certificate_request(crypto.FILETYPE_PEM, request_cert_str) +- +- cert = crypto.X509() +- cert.set_subject(req_cert.get_subject()) +- cert.set_serial_number(sn) +- cert.gmtime_adj_notBefore(valid_from) +- cert.gmtime_adj_notAfter(valid_to) +- cert.set_issuer(ca_cert.get_subject()) +- cert.set_pubkey(req_cert.get_pubkey()) +- cert.sign(ca_key, hash_alg) +- +- cert_dump = crypto.dump_certificate(crypto.FILETYPE_PEM, cert) +- if isinstance(cert_dump, str): +- return cert_dump +- return cert_dump.decode("utf-8") ++ if isinstance(sign_cert_str, str): ++ sign_cert_str = sign_cert_str.encode("utf-8") ++ ca_cert = x509.load_pem_x509_certificate(sign_cert_str) ++ ca_key = serialization.load_pem_private_key( ++ sign_key_str, password=passphrase) ++ req_cert = x509.load_pem_x509_csr(request_cert_str) ++ ++ now = datetime.now(timezone.utc) ++ cert = x509.CertificateBuilder().subject_name( ++ req_cert.subject, ++ ).serial_number( ++ sn, ++ ).not_valid_before( ++ now + timedelta(seconds=valid_from), ++ ).not_valid_after( ++ now + timedelta(seconds=valid_to), ++ ).issuer_name( ++ ca_cert.subject, ++ ).public_key( ++ req_cert.public_key(), ++ ).sign(ca_key, hashes.SHA256()) ++ ++ return cert.public_bytes(serialization.Encoding.PEM).decode("utf-8") + + def verify_chain(self, cert_chain_str_list, cert_str): + """ +@@ -276,13 +293,6 @@ class OpenSSLWrapper: + cert_str = tmp_cert_str + return (True, "Signed certificate is valid and correctly signed by CA " "certificate.") + +- def certificate_not_valid_yet(self, cert): +- starts_to_be_valid = dateutil.parser.parse(cert.get_notBefore()) +- now = datetime.now(timezone.utc) +- if starts_to_be_valid < now: +- return False +- return True +- + def verify(self, signing_cert_str, cert_str): + """ + Verifies if a certificate is valid and signed by a given certificate. +@@ -303,34 +313,34 @@ class OpenSSLWrapper: + Message = Why the validation failed. + """ + try: +- ca_cert = crypto.load_certificate(crypto.FILETYPE_PEM, signing_cert_str) +- cert = crypto.load_certificate(crypto.FILETYPE_PEM, cert_str) +- +- if self.certificate_not_valid_yet(ca_cert): ++ if isinstance(signing_cert_str, str): ++ signing_cert_str = signing_cert_str.encode("utf-8") ++ if isinstance(cert_str, str): ++ cert_str = cert_str.encode("utf-8") ++ ca_cert = x509.load_pem_x509_certificate(signing_cert_str) ++ cert = x509.load_pem_x509_certificate(cert_str) ++ now = datetime.now(timezone.utc) ++ ++ if ca_cert.not_valid_before_utc >= now: + return False, "CA certificate is not valid yet." + +- if ca_cert.has_expired() == 1: ++ if ca_cert.not_valid_after_utc < now: + return False, "CA certificate is expired." + +- if cert.has_expired() == 1: ++ if cert.not_valid_after_utc < now: + return False, "The signed certificate is expired." + +- if self.certificate_not_valid_yet(cert): ++ if cert.not_valid_before_utc >= now: + return False, "The signed certificate is not valid yet." + +- if ca_cert.get_subject().CN == cert.get_subject().CN: ++ if ca_cert.subject.get_attributes_for_oid(NameOID.COMMON_NAME) == \ ++ cert.subject.get_attributes_for_oid(NameOID.COMMON_NAME): + return False, ("CN may not be equal for CA certificate and the " "signed certificate.") + +- cert_algorithm = cert.get_signature_algorithm() +- cert_algorithm = cert_algorithm.decode("ascii") +- cert_str = cert_str.encode("ascii") +- +- cert_crypto = saml2.cryptography.pki.load_pem_x509_certificate(cert_str) +- + try: +- crypto.verify(ca_cert, cert_crypto.signature, cert_crypto.tbs_certificate_bytes, cert_algorithm) ++ cert.verify_directly_issued_by(ca_cert) + return True, "Signed certificate is valid and correctly signed by CA certificate." +- except crypto.Error as e: ++ except (ValueError, TypeError, InvalidSignature) as e: + return False, f"Certificate is incorrectly signed: {str(e)}" + except Exception as e: + return False, f"Certificate is not valid for an unknown reason. {str(e)}" +@@ -352,8 +362,14 @@ def read_cert_from_file(cert_file, cert_type="pem"): + data = fp.read() + + try: +- cert = saml2.cryptography.pki.load_x509_certificate(data, cert_type) +- pem_data = saml2.cryptography.pki.get_public_bytes_from_cert(cert) ++ cert = None ++ if cert_type == "pem": ++ cert = x509.load_pem_x509_certificate(data) ++ elif cert_type == "der": ++ cert = x509.load_der_x509_certificate(data) ++ else: ++ raise ValueError(f"cert-type {cert_type} not supported") ++ pem_data = cert.public_bytes(serialization.Encoding.PEM).decode("utf-8") + except Exception as e: + raise CertificateError(e) + +diff --git a/src/saml2/sigver.py b/src/saml2/sigver.py +index 738ac04b..60c83718 100644 +--- a/src/saml2/sigver.py ++++ b/src/saml2/sigver.py +@@ -18,8 +18,9 @@ from time import mktime + from urllib import parse + from uuid import uuid4 as gen_random_key + +-from OpenSSL import crypto +-import dateutil ++from urllib import parse ++ ++from cryptography import x509 + + from saml2 import ExtensionElement + from saml2 import SamlBase +@@ -373,14 +374,14 @@ def active_cert(key): + """ + try: + cert_str = pem_format(key) +- cert = crypto.load_certificate(crypto.FILETYPE_PEM, cert_str) ++ cert = x509.load_pem_x509_certificate(cert_str) + except AttributeError: + return False + +- now = datetime.now(timezone.utc) +- valid_from = dateutil.parser.parse(cert.get_notBefore()) +- valid_to = dateutil.parser.parse(cert.get_notAfter()) +- active = not cert.has_expired() and valid_from <= now < valid_to ++ now = datetime.datetime.now(datetime.timezone.utc) ++ valid_from = cert.not_valid_before_utc ++ valid_to = cert.not_valid_after_utc ++ active = valid_from <= now < valid_to + return active + + From aab9d753894933c292188ee5cbf583a1c9a9f8d7 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 9 Nov 2025 07:10:37 +0000 Subject: [PATCH 08/13] terraform-providers.newrelic_newrelic: 3.74.0 -> 3.75.2 --- .../networking/cluster/terraform-providers/providers.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/networking/cluster/terraform-providers/providers.json b/pkgs/applications/networking/cluster/terraform-providers/providers.json index 306afcfc4a30..63bbde99dad4 100644 --- a/pkgs/applications/networking/cluster/terraform-providers/providers.json +++ b/pkgs/applications/networking/cluster/terraform-providers/providers.json @@ -949,13 +949,13 @@ "vendorHash": "sha256-OAd8SeTqTrH0kMoM2LsK3vM2PI23b3gl57FaJYM9hM0=" }, "newrelic_newrelic": { - "hash": "sha256-1OpvSayWq194591u/z9oHz80ZmPA9fSZpKSBwDHL/tk=", + "hash": "sha256-OdvDvo40fjuKoRjI1r1re/h2i5JopssRF5dQye4AsSM=", "homepage": "https://registry.terraform.io/providers/newrelic/newrelic", "owner": "newrelic", "repo": "terraform-provider-newrelic", - "rev": "v3.74.0", + "rev": "v3.75.2", "spdx": "MPL-2.0", - "vendorHash": "sha256-7zUUV3cqVesItNnE/EcO5/l+nafV04JdoNkmTxnulio=" + "vendorHash": "sha256-LBOxoSGvJ5AWS71UINBbVgDxLZqDpNgq7lY8LaPZsvs=" }, "ns1-terraform_ns1": { "hash": "sha256-S0ji/gZsbMTgug7DwPODAcPx3IfRaw1JHYPJ6V+tqeM=", From fca1a39d24c5ce505cee33e7e98d44e45d9284f1 Mon Sep 17 00:00:00 2001 From: eljamm Date: Sat, 8 Nov 2025 22:25:01 +0100 Subject: [PATCH 09/13] yaziPlugins.compress: init at 0.5.0-unstable-2025-08-15 --- .../ya/yazi/plugins/compress/default.nix | 23 +++++++++++++++++++ 1 file changed, 23 insertions(+) create mode 100644 pkgs/by-name/ya/yazi/plugins/compress/default.nix diff --git a/pkgs/by-name/ya/yazi/plugins/compress/default.nix b/pkgs/by-name/ya/yazi/plugins/compress/default.nix new file mode 100644 index 000000000000..137c33a13201 --- /dev/null +++ b/pkgs/by-name/ya/yazi/plugins/compress/default.nix @@ -0,0 +1,23 @@ +{ + lib, + fetchFromGitHub, + mkYaziPlugin, +}: +mkYaziPlugin { + pname = "compress.yazi"; + version = "0.5.0-unstable-2025-08-15"; + + src = fetchFromGitHub { + owner = "KKV9"; + repo = "compress.yazi"; + rev = "c2646395394f22b6c40bff64dc4c8c922d210570"; + hash = "sha256-qAuMD4YojLfVaywurk5uHLywRRF77U2F7ql+gR8B/lo="; + }; + + meta = { + description = "Yazi plugin that compresses selected files to an archive"; + homepage = "https://github.com/KKV9/compress.yazi"; + license = lib.licenses.mit; + maintainers = with lib.maintainers; [ eljamm ]; + }; +} From 19d01345848650537fed8397dc124fc5c4523ea0 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 9 Nov 2025 09:00:44 +0000 Subject: [PATCH 10/13] emmylua-ls: 0.16.0 -> 0.17.0 --- pkgs/by-name/em/emmylua-ls/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/em/emmylua-ls/package.nix b/pkgs/by-name/em/emmylua-ls/package.nix index 71fe171f0465..3fbeb620266c 100644 --- a/pkgs/by-name/em/emmylua-ls/package.nix +++ b/pkgs/by-name/em/emmylua-ls/package.nix @@ -7,18 +7,18 @@ }: rustPlatform.buildRustPackage (finalAttrs: { pname = "emmylua_ls"; - version = "0.16.0"; + version = "0.17.0"; src = fetchFromGitHub { owner = "EmmyLuaLs"; repo = "emmylua-analyzer-rust"; tag = finalAttrs.version; - hash = "sha256-6mcVIOKsC+1cboZ8e23J0m2ed/2ohR0F3LfrM9UlaR4="; + hash = "sha256-CAYSaRjpQwnPZojeX/VyV9/xz8SY8Lt+e1wc79qvGZg="; }; buildAndTestSubdir = "crates/emmylua_ls"; - cargoHash = "sha256-d6dhrib4mz7KmHo3EbkUXBPpjEGu35GeYNkpIrJrKJI="; + cargoHash = "sha256-nGSN7LqvAwYg2Z+2tTAc+vIwrYmb+W0OLw9EeG7e/V8="; nativeInstallCheckInputs = [ versionCheckHook From ce5cc48a42f6e9f0aa5ad947756ed22de78bb471 Mon Sep 17 00:00:00 2001 From: Jost Alemann Date: Sun, 9 Nov 2025 11:43:28 +0100 Subject: [PATCH 11/13] scion: update meta.homepage Previous homepage shows a message that it has moved --- pkgs/by-name/sc/scion/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/sc/scion/package.nix b/pkgs/by-name/sc/scion/package.nix index cad28b77aa4f..4b0fd2a7eabb 100644 --- a/pkgs/by-name/sc/scion/package.nix +++ b/pkgs/by-name/sc/scion/package.nix @@ -49,7 +49,7 @@ buildGoModule (finalAttrs: { meta = { description = "Future Internet architecture utilizing path-aware networking"; - homepage = "https://scion-architecture.net/"; + homepage = "https://www.scion.org/"; platforms = lib.platforms.unix; license = lib.licenses.asl20; maintainers = with lib.maintainers; [ From 1e532f3dcf17b110687e52eeef1959548ba3afc6 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 9 Nov 2025 11:11:11 +0000 Subject: [PATCH 12/13] ghostfolio: 2.214.0 -> 2.215.0 --- pkgs/by-name/gh/ghostfolio/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/gh/ghostfolio/package.nix b/pkgs/by-name/gh/ghostfolio/package.nix index 29918109ef51..617b155a0f38 100644 --- a/pkgs/by-name/gh/ghostfolio/package.nix +++ b/pkgs/by-name/gh/ghostfolio/package.nix @@ -11,13 +11,13 @@ buildNpmPackage rec { pname = "ghostfolio"; - version = "2.214.0"; + version = "2.215.0"; src = fetchFromGitHub { owner = "ghostfolio"; repo = "ghostfolio"; tag = version; - hash = "sha256-x8GUlC1/TxA40rDQu3Ae2P5v5LFtberOQWtx5GJ7rMw="; + hash = "sha256-j7UmjyayVbun4PrNSPwOi2+EGUhyTFuLQLSIZp8l95g="; # populate values that require us to use git. By doing this in postFetch we # can delete .git afterwards and maintain better reproducibility of the src. leaveDotGit = true; @@ -27,7 +27,7 @@ buildNpmPackage rec { ''; }; - npmDepsHash = "sha256-hHfT4gsf0D5XPY4RuQCKWNWp+iav9B75YMs70xayqtc="; + npmDepsHash = "sha256-58e/LBgB4MQIp3xUdQXVvmq7krQ8+i0ku9xineC1HRU="; nativeBuildInputs = [ prisma From fa819afd505d9d7dbadf79d62ac7ab9d751896ce Mon Sep 17 00:00:00 2001 From: Letgamer Date: Sat, 8 Nov 2025 22:01:54 +0100 Subject: [PATCH 13/13] evil-winrm-py: init at 1.5.0 --- pkgs/by-name/ev/evil-winrm-py/package.nix | 57 +++++++++++++++++++++++ 1 file changed, 57 insertions(+) create mode 100644 pkgs/by-name/ev/evil-winrm-py/package.nix diff --git a/pkgs/by-name/ev/evil-winrm-py/package.nix b/pkgs/by-name/ev/evil-winrm-py/package.nix new file mode 100644 index 000000000000..8b54b252b938 --- /dev/null +++ b/pkgs/by-name/ev/evil-winrm-py/package.nix @@ -0,0 +1,57 @@ +{ + lib, + python3Packages, + fetchFromGitHub, + libkrb5, + versionCheckHook, + nix-update-script, + enableKerberos ? true, +}: + +python3Packages.buildPythonApplication rec { + pname = "evil-winrm-py"; + version = "1.5.0"; + pyproject = true; + + src = fetchFromGitHub { + owner = "adityatelange"; + repo = "evil-winrm-py"; + tag = "v${version}"; + hash = "sha256-IACFPPlkgyJh78p6Jy740CQqcySkMTV/8VVPSRJKTPI="; + }; + + # Removes the additional binary ewp + postPatch = '' + substituteInPlace setup.py \ + --replace-fail '"ewp = evil_winrm_py.evil_winrm_py:main",' "" + ''; + + build-system = [ python3Packages.setuptools ]; + + dependencies = + with python3Packages; + [ + pypsrp + prompt-toolkit + tqdm + ] + ++ lib.optionals enableKerberos pypsrp.optional-dependencies.kerberos; + + # Add the C library if Kerberos is enabled + buildInputs = lib.optionals enableKerberos [ libkrb5 ]; + + nativeInstallCheckInputs = [ versionCheckHook ]; + versionCheckProgramArg = "--version"; + doInstallCheck = true; + + passthru.updateScript = nix-update-script { }; + + meta = { + description = "Execute commands interactively on remote Windows machines using the WinRM protocol"; + homepage = "https://github.com/adityatelange/evil-winrm-py"; + changelog = "https://github.com/adityatelange/evil-winrm-py/releases/tag/v${version}"; + license = lib.licenses.mit; + maintainers = with lib.maintainers; [ letgamer ]; + mainProgram = "evil-winrm-py"; + }; +}